1. Internal & External Issues (4.1)
Has the organization identified and documented the privacy-specific internal and external issues that are relevant to its purpose, including the nature and categories of PII processed, applicable legal and regulatory obligations, and any emerging privacy risks arising from AI, cloud, IoT, biometric, or health data processing activities?
2. Interested Parties' Needs (4.2)
Has the organization determined the needs and expectations of relevant interested parties – including PII principals, regulatory bodies, customers, and processors – and identified which of these needs and expectations are applicable requirements for the PIMS?
3. Scope of PIMS (4.3)
Has the organization clearly defined and documented the scope of the PIMS, including the organizational boundaries, the categories of PII processed, the roles of PII Controller and/or PII Processor applicable to the organization, and any activities or processing operations that are excluded from scope?
4. PIMS Establishment & Continual Improvement (4.4)
Has the organization established, implemented, maintained, and continually improved a PIMS that integrates the required processes, roles, responsibilities, and improvement mechanisms to protect PII across all in-scope activities, including those performed by third parties on the organization’s behalf?
5. Leadership & Commitment (5.1)
Has top management demonstrated leadership and commitment to the PIMS by establishing a privacy policy, ensuring that privacy objectives are set and aligned with the organization’s strategic direction, providing the resources necessary to operate the PIMS, and actively promoting a privacy-aware culture across the organization?
6. Privacy Policy (5.2)
Has the organization established a documented privacy policy that is appropriate to its purpose, includes commitments to satisfying applicable PII protection requirements and to continual improvement of the PIMS, and has been communicated to all relevant personnel and interested parties?
7. Roles, Responsibilities & Authorities (5.3)
Have roles, responsibilities, and authorities for the PIMS been clearly defined and assigned, including the designation of a privacy lead or Data Protection Officer (DPO) where required, ensuring that accountability for privacy governance is established at appropriate levels of management?
8. Actions to Address Risks and Opportunities (6.1.1)
Has the organization identified the privacy risks and opportunities that could affect its ability to achieve its PIMS objectives, and established, implemented, and maintained plans to address them?
9. Privacy Risk Assessment Methodology (6.1.2)
Is there a defined, consistent, and repeatable methodology for conducting privacy risk assessments that includes identifying risks to the rights and freedoms of PII principals, assessing the likelihood and impact of those risks, and evaluating the effectiveness of existing controls?
10. Privacy Controls Selection (6.1.3)
Have suitable privacy controls been selected and implemented to treat identified risks, and have they been verified against Annex A of ISO/IEC 27701:2025 – which consolidates controls for PII Controllers (A.1), PII Processors (A.2), and shared controls (A.3) – to ensure no applicable privacy controls have been overlooked?
11. Statement of Applicability (6.1.4)
Has a Statement of Applicability for privacy controls been developed and maintained that identifies selected controls from Annex A for PII Controller and/or PII Processor obligations, justifies the inclusion or exclusion of each applicable control, documents any additional controls implemented beyond Annex A, and confirms the current implementation status of each control?
12. Measurable Privacy Objectives (6.2)
Have measurable PIMS privacy objectives been established, communicated to relevant stakeholders, and aligned with the privacy policy and applicable regulatory requirements, including consideration of any jurisdiction-specific obligations?
13. Plan to Achieve Privacy Objectives (6.2)
Is there a documented plan specifying the actions required to achieve privacy objectives, including who is responsible, the timescales, the resources required, and how results will be evaluated and reported to management?
14. Resources Provision (7.1)
Has the organization provided the people, infrastructure, technology, and expertise necessary to establish, implement, maintain, and continually improve the PIMS, including dedicated privacy-specific resources and capabilities?
15. Competence & Training (7.2)
Are individuals performing roles relevant to PII processing determined to be competent through appropriate education, training, or experience, with competence records maintained and periodic review conducted to ensure ongoing adequacy?
16. Privacy Awareness (7.3)
Are all personnel whose activities may affect PII protection aware of: the organization’s privacy policy and their specific obligations under it, their individual contribution to PIMS effectiveness, and the consequences of failing to comply with PIMS requirements, including potential impacts on PII principals?
17. Communication Plan (7.4)
Has the organization defined and implemented a communication plan for the PIMS that specifies what privacy-related information is communicated, to whom, by what means, and at what frequency, including both internal communications and external notifications to PII principals and regulatory authorities?
18. Control of Documented Information (7.5)
Is documented information relating to PIMS processes, PII processing records, privacy risk assessments, control evidence, and incident records properly created, approved, protected, controlled, retained, and available for audit and regulatory review purposes?
19. Operational Planning and Control (8.1)
Has the organization planned, implemented, controlled, and maintained the processes needed to meet PIMS requirements, and are documented records retained to demonstrate that processes are being carried out as planned?
20. Management of Planned Changes (8.1)
When significant changes to PII processing activities, systems, or organizational context are planned, are these changes assessed for privacy impact, approved prior to implementation, and reviewed to manage any adverse effects on privacy controls?
21. Lawful Basis and Purpose Limitation (8.2)
Has the organization, acting as a PII Controller, identified and documented a lawful basis for each PII processing activity, and ensured that PII is collected only for specified, explicit, and legitimate purposes, with collection limited to what is strictly necessary for those purposes?
22. Consent Management (8.2)
Are mechanisms in place to obtain, record, manage, and – where relied upon as the lawful basis – withdraw PII principal consent, including processes to cease processing, delete or return PII, and notify affected third parties upon withdrawal?
23. Privacy by Design & Default (8.2)
Has the organization implemented privacy by design principles, ensuring that privacy controls, data minimization, and purpose limitation are built into the design of systems, services, and processes that involve PII from the earliest stage, including AI systems, cloud deployments, IoT devices, and applications processing biometric or health data?
24. Privacy Notices & Transparency (8.3)
Has the organization established processes to provide PII principals with clear, complete, and accessible privacy notices at the point of collection, including the identity and contact details of the PII Controller, the purposes and legal basis for processing, retention periods, details of any third-party disclosures or cross-border transfers, and the rights available to PII principals?
25. Obligations to PII Principals (8.3)
Are documented procedures in place to receive, authenticate, track, and respond to PII principal rights requests – including access, rectification, erasure, restriction of processing, data portability, and objection – within the timeframes required by applicable regulations?
26. Safeguards for Sharing & Cross-Border Transfers (8.4)
Where the organization discloses or transfers PII to third parties or across national borders, has it ensured that appropriate safeguards are in place – such as adequacy decisions, standard contractual clauses, binding corporate rules, or equivalent mechanisms – to maintain the required level of PII protection?
27. Third-Party PII Processor Contracts (8.4)
Are contracts or binding agreements with third-party PII processors in place that require processors to implement appropriate technical and organizational privacy controls, process PII only on the organization’s documented instructions, support the exercise of PII principal rights, and permit audits or inspections to verify compliance?
28. Monitoring and Measurement Criteria (9.1)
Has the organization established privacy-specific monitoring and measurement criteria, including what PII processing activities and controls are evaluated, the methods used, the frequency of measurement, who is responsible for analysis, and how results are documented and acted upon?
29. Privacy Performance Indicators (9.1)
Have measurable privacy performance indicators been defined and implemented – including metrics for PII principal rights request volumes and response times, privacy incident rates, data breach notification timelines, and control effectiveness – and are these reported to management at planned intervals?
30. Internal PIMS Audits (9.2)
Are internal PIMS audits conducted at planned intervals by competent and objective auditors, covering all applicable clauses of ISO/IEC 27701:2025, with findings documented, communicated to management, and tracked through to resolution?
31. PIMS Management Review (9.3)
Does top management review the PIMS at planned intervals, considering changes in the internal and external context, privacy performance against objectives, the results of audits and risk assessments, privacy incident trends, regulatory developments, and decisions on continual improvement?
32. Corrective Action and Investigation (10.1)
When a privacy nonconformity, PII breach, or PIMS failure occurs, does the organization take timely corrective action, investigate and address the root cause, assess whether similar issues could occur elsewhere, verify the effectiveness of actions taken, and document the outcomes and lessons learned?
33. Privacy Incident Management Process (10.2)
Is there a formal privacy incident management process covering detection, triage, classification, internal escalation, notification of affected PII principals and relevant supervisory authorities within required timeframes, post-incident review, and integration of lessons learned into PIMS improvements?